exploitsTectonic's $75M Exploit: A $1.34M Token Underwrote $119M of LoansAn attacker pumped Tectonic's own governance token about 100x in 20 minutes, borrowed against it, and emptied the largest lending market on Cronos. Validators halted the chain.Dmitry Serdyuk·Aug 31, 20263m
technicalLedger's Clear Signing Race: One Extra APDU Could Swap the Transaction You ApprovedLedger shipped twenty-one fixes in Ethereum app 1.22.2 under a two-word changelog line. The git history shows what they closed: a second command could replace the transaction behind the screen.Dmitry Serdyuk·Aug 25, 20263m
exploitsTornado Cash Frontend Phishing: 810 ETH Drained After the Domain LapsedReports put the loss at 1,010 ETH. The pools tell a tighter story: nine withdrawals, 810 ETH, eight minutes, and a collection wallet the attacker funded out of the mixer itself six days earlier.Dmitry Serdyuk·Aug 24, 20264m
exploitsMaya Protocol $1.7M Exploit: Six Chained Bugs Became One Uncapped Slash SubsidyOne 23-message transaction chained six medium bugs into a critical: a false theft alert minted 49.45M CACAO into a thin pool the attacker then owned 99.93% of, draining 20.83 BTC.Dmitry Serdyuk·Aug 20, 20263m
exploitsFoxMarket $119K Exploit: A Stale LP Bond Price Minted Free FOXFoxMarket lost about $119K on BNB Chain when its LP bond pool priced a mint from a PancakeSwap spot quote read before the attacker's own swap moved that same pool.Dmitry Serdyuk·Aug 19, 20263m
exploitsCoreum Bridge $200K Exploit: 17 Signers and One Missing Destination CheckThe tx XRPL bridge lost 199,916 XRP in 94 multisig payments because its relayer confirmed that a memo appeared in the bridge's transaction history, never that money reached the bridge.Dmitry Serdyuk·Aug 18, 20263m
exploitsSafePal Order Data Leak: 39,798 Wallet Buyers Exposed by an Authorization FlawAn authorization flaw in a third-party order-tracking plug-in let anyone read another SafePal customer's order by changing the order number. What left the building was the hardware wallet buyer list.Dmitry Serdyuk·Aug 17, 20263m
exploitsRavencoin's KAWPOW Bug: A Block That Lies About Its Own Height Skips the Mining WorkA header field nodes never checked let blocks skip ProgPoW entirely and mine at a fraction of the honest cost. Two mining pools answered by rewinding about three days of chain history.Dmitry Serdyuk·Aug 14, 20264m
exploitsHarmony's 4 Billion ONE Mint: The Replay Fix the Attacker Could Switch OffAn attacker minted about 4 billion ONE, roughly 26% of supply. Harmony's replay defense read its activation epoch from inside the proof, so the proof decided whether the defense applied.Dmitry Serdyuk·Aug 13, 20263m
exploitsIll Bloom: A 12-Year-Old CryptoJS PRNG Bug Drained $5.7M in Guessable SeedsCryptoJS seeded its randomness from Math.random(), cutting 128-bit wallet entropy to about 2^39. Attackers enumerated the phrases and swept 1,034 accounts. Upgrading does not fix a key already made.Dmitry Serdyuk·Aug 11, 20263m
exploitsBTCPay Server's Stolen Macaroons: Why Updating to 2.4.2 Does Not End ItAttackers stole LND macaroon credentials from BTCPay servers, closed merchant Lightning channels and swept the funds. Version 2.4.2 shuts the door. It does not revoke the keys already copied.Dmitry Serdyuk·Aug 10, 20263m
exploitsSwan Treasury's $625K Signer Key Leak: One Key, Three Contracts, Five Cents of GasA leaked off-chain signer key let an attacker sign their own discount. Swan Treasury's buy() function checked who signed the message and never checked what the message asked for.Dmitry Serdyuk·Aug 7, 20263m
exploitsVerus Bridge $7.5M Exploit: When Two Chains Read the Same Bytes DifferentlyAn attacker poisoned Verus notarizations with duplicate state roots that Verus and Ethereum parsed differently, draining $7.5M from a bridge already drained for $11.58M nine weeks earlier.Dmitry Serdyuk·Aug 6, 20263m
exploitsColdcard's $88.6M Entropy Failure: Five Years of Guessable Bitcoin SeedsA March 2021 build error routed Coldcard seed generation to a software PRNG instead of the hardware RNG. Five years later, attackers swept 1,367 BTC from 4,585 addresses without touching a device.Aron Turner·Aug 3, 20264m
exploitsTriple-A's $11.8M Hot Wallet Drain: Seven Chains, and 31 Hours Nobody Closed the TapTriple-A's treasury wallets were swept across seven chains starting July 24, 2026. The theft took hours. Deposits kept arriving and kept being swept for 31.Dmitry Serdyuk·Jul 30, 20263m
exploitsB2 Network $3.86M Staking Drain: The Upgrade Key Did All the WorkB2 Network lost 8.59M B2 tokens, about $3.86M, when someone used the staking contract's upgrade authority. That privilege had sat on the same wallet since 2025.Dmitry Serdyuk·Jul 27, 20263m
exploitsAFX Trade $24.15M Bridge Exploit: Compromised Validator Keys Signed a Valid DrainAFX Trade's bridge lost $24.15M in USDC on Arbitrum. No contract bug: five operator-held validator keys signed a real quorum, and the bridge did exactly as told.Dmitry Serdyuk·Jul 24, 20263m
exploitsThe Fake Recruiter Repo That Hid Its Malware in a Tailwind ConfigA fake Web3 recruiter sends a GitHub repo to try before the interview. The malware hides as a 4 MB Tailwind plugin, fires on the dev command, and hunts wallets, SSH keys, and seed phrases.Dmitry Serdyuk·Jul 23, 20264m
exploitsThe TRAE Extension Backdoor That Ran Its C2 on an Ethereum ContractA fake Solidity plugin, juannegro.solidity, backdoors Windows, macOS, and Linux dev machines and reads its C2 address from an Ethereum contract the attacker updates on-chain.Dmitry Serdyuk·Jul 22, 20263m
exploitsAllbridge Core $1.65M Exploit: A 2023 Flash Loan Fix That Missed SolanaAllbridge Core lost $1.65M on Solana to the same flash loan trick it said it fixed in 2023. The one-pool promise held on BNB Chain and not on Solana.Dmitry Serdyuk·Jul 21, 20263m
exploitsDefiTuna Exploit: $580K Drained From Solana Lending PoolDefiTuna's USDC lending pool lost $580K to a July 2026 exploit on Solana, leaving it in bad debt. Inside the attack, the Sec3 audit gap, and the lessons.Aron Turner·Jul 20, 20263m
exploitsInjective npm SDK Backdoored to Steal Wallet Keys: Anatomy of a Near MissA compromised maintainer account backdoored 18 @injectivelabs npm packages on July 8, 2026, harvesting wallet seed phrases at key-derivation time. It failed by minutes. Here is how it nearly worked.Dmitry Serdyuk·Jul 14, 20263m
exploitsSummer.fi's $6M Lazy Summer Exploit: When a Donation Broke the Vault MathAn attacker donated an asset into a Summer.fi Lazy Summer vault, inflated its totalAssets() share price, and redeemed a flash loan for a $6M profit. No key was stolen. The accounting was the hole.Dmitry Serdyuk·Jul 8, 20264m
exploitsBonkDAO's $20M Governance Takeover: When Buying the Vote Beats Hacking the CodeAn attacker spent about $4M buying BONK, took a voting majority on BonkDAO's Realms governance, and passed one proposal that moved $20M out of the treasury. No contract was hacked. The rules were.Dmitry Serdyuk·Jul 7, 20264m
exploitsAztec Connect's $2.19M Exploit: A ZK-Rollup Settlement Bug in a Contract No One Could PatchA deprecated Aztec Connect contract was drained of $2.19M when its L1 settlement loop and its ZK proof disagreed on how many slots were real. Its keys were renounced, so no one could pause it.Dmitry Serdyuk·Jul 5, 20264m
exploitsJaredFromSubway MEV Bot Drained for $7.5M in a Counter-MEV HoneypotJaredFromSubway, Ethereum's most prolific MEV sandwich bot, was drained of $7.5M when an attacker turned its own logic into a counter-MEV honeypot. How the dangling-approval attack worked.Aron Turner·Jun 23, 20263m
researchThe Map Already Exists: Building a Digital-Economy Startup in Australia in 2026Australia ranks 16th on innovation inputs but 27th on outputs. The gap is not talent, it is plumbing. A field guide to the grants, funds and pathways open today, and what to copy from abroad.Alex Rybalko·Jun 17, 202645m
researchSolana Smart Contract Vulnerabilities: The Patterns Behind $500M in ExploitsWormhole $320M, Mango $114M, Cashio $52M. None of them were Rust bugs. The seven vulnerability classes behind Solana's biggest exploits, and what an audit checks for each.Alex Rybalko·Jun 12, 20263m
exploitsHumanity Protocol's $36M Key Compromise: A Runbook for Wallets That Touch ContractsOne compromised laptop held seven keys and cleared two multisigs, draining $36M+ from Humanity Protocol. A runbook for segregating, monitoring, and revoking project wallets that touch contracts.Dmitry Serdyuk·Jun 10, 20263m
exploitsThe $3.2M SquidRouterModule Exploit: How a Public String Drained 86 Safe WalletsA third-party module named SquidRouterModule drained $3.2M from 86 Gnosis Safe wallets on Ethereum and Base. Full attack chain, the auth flaw, and the lesson.Aron Turner·May 26, 20263m
exploitsGitHub's 3,800-Repo Breach: How a Poisoned VS Code Extension Burned the World's Biggest Code HostOne poisoned VS Code extension on one GitHub employee's laptop cost the company ~3,800 internal repositories. Here is the attack chain, the Mini Shai-Hulud worm internals, and the rotate-everything checklist that follows.Aron Turner·May 21, 20264m
researchReserve Manipulation Isn't DeadSeven BSC pools drained $3M in 2026 H1 — same reserve-manipulation primitive every time. Here's what auditors keep missing.Alex Rybalko·May 20, 20262m
researchAudit the Release Pipeline Like a Smart ContractYour contracts are audited. Your release pipeline isn't. Mini Shai-Hulud proved npm provenance signs whatever a compromised workflow ships. Here's the checklist Web3 teams should run on their own pipeline.Dmitry Serdyuk·May 19, 20263m
researchCopy Fail: When a Linux Bug Becomes Protocol RiskCopy Fail is a Linux kernel privilege escalation, not a smart contract bug. For Web3 teams running validators, CI runners, deployer hosts, and signing infrastructure, that's exactly why it matters.Dmitry Serdyuk·May 5, 20263m
exploitsKelp DAO's $292M Hack and Aave's $6B Fallout: One Config Parameter Broke DeFiA 1-of-1 LayerZero DVN let attackers drain 116,500 rsETH ($292M) from Kelp DAO, loop it through Aave V3 for $266M in ETH, and wipe $6B in Aave TVL in 24 hours. No Solidity bug. One config parameter broke DeFi.Aron Turner·Apr 20, 20264m
case-studiesThe Delve Scandal: How a $300M Compliance Startup Sold Fake SOC 2 Reports and Got Expelled from YCYC expelled Delve after an investigation revealed 493 of 494 SOC 2 reports were identical boilerplate. Here's the full breakdown of the $300M compliance fraud.Alex Rybalko·Apr 9, 20263m
exploitsDrift Protocol's $270M Exploit: How Solana's Durable Nonces Became a Social Engineering WeaponAn attacker drained $270M from Drift Protocol by abusing Solana's durable nonce feature to pre-sign malicious multisig transactions weeks before execution.Aron Turner·Apr 3, 20263m
industryHow to Choose a Smart Contract Audit Firm Without Getting BurnedA framework for evaluating audit firms based on methodology, track record, and specialization, not marketing. What to look for, what to avoid, and the questions most teams forget to ask.Kolin Cunningham·Mar 20, 20263m
technicalSmart Contract Audit Checklist: What to Prepare Before Your EngagementThe preparation checklist that separates smooth audit engagements from costly delays. What your team needs to have ready before auditors touch your code.Dmitry Serdyuk·Mar 20, 20263m
industryWhat Does a Smart Contract Audit Actually Cost in 2026Real audit pricing data from 2026. What affects cost, what you should expect to pay, and how to evaluate whether an audit is worth the investment for your protocol.Aron Turner·Mar 20, 20263m
researchClaude Code Security vs Codex Security: What Each AI Vulnerability Scanner Actually DeliversAnthropic and OpenAI both shipped AI-powered vulnerability scanners in early 2026. We break down what each tool actually does, where they fall short, and why neither one replaces a smart contract audit.Dmitry Serdyuk·Mar 18, 20264m
exploitsAave's $27M Liquidation Incident: How a Stale Oracle Parameter Wiped Out 34 UsersA desynchronized oracle parameter caused Aave to undervalue wstETH by 2.85%, triggering $27M in wrongful liquidations across 34 users. Full technical breakdown.Aron Turner·Mar 12, 20263m
industryWhat to Expect From a Smart Contract Audit ReportWhat a professional audit report actually contains, how findings are classified, and how to use the report to ship secure code, not just check a compliance box.Aron Turner·Mar 10, 20263m
researchAI's Growing Role in Auditing and CybersecurityWith smart contract deployments hitting a record 8.7M per quarter, manual review can't keep up. Discover why AI-assisted auditing is the only realistic way to close the Web3 security gap.Aron Turner·Mar 2, 20263m
researchThe Human Factor: Why Web3's Biggest Threat in 2026 Isn't Bad Code — It's PeopleIn 2025, social engineering drove 55% ($1.39B) of crypto losses. As attackers pivot from smart contracts to phishing, learn why true Web3 security requires more than just code audits.Kolin Cunningham·Feb 26, 20263m
researchWhat $10.77 Billion in Hacks Reveals About Audit EffectivenessAnalysis of 100 largest protocol hacks totaling $10.77B. Only 20% were audited, but the ones that were share a pattern. Firm comparison, verified exploit data, pricing, and evaluation criteria.Alex Rybalko·Feb 25, 20263m